8.7

CVSS4.0

CVE-2025-40798 -

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC componโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:48 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 10:15 a.m.

8.7

CVSS4.0

CVE-2025-40797 -

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC componโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:48 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 10:15 a.m.

8.7

CVSS4.0

CVE-2025-40796 -

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC componโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:48 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 10:15 a.m.

9.3

CVSS4.0

CVE-2025-40795 -

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated Uโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:48 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 10:15 a.m.

6.3

CVSS4.0

CVE-2025-40757 -

A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices connected to the network allow unrestricted access to sensitive files, such as databases. This could allow an aโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:47 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 9:31 p.m.

6.9

CVSS4.0

CVE-2025-40594 -

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege manageโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:47 a.m. ๐Ÿ”„ Last Modified: March 10, 2026, 6:17 p.m.

9.1

CVSS3.1

CVE-2025-10134 - Goza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrโ€ฆ

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to deโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: Sept. 9, 2025, 9:31 p.m.

8

CVSS3.1

CVE-2025-9539 - AutomatorWP โ€“ Automator plugin for no-code automations, webhooks & custom integrations in WordPressโ€ฆ

The AutomatorWP โ€“ Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and inโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3:15 a.m.

5.4

CVSS3.1

CVE-2025-9542 - AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions

The AutomatorWP โ€“ Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. Thโ€ฆ

๐Ÿ“… Published: Sept. 9, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3:15 a.m.

3.5

CVSS3.1

CVE-2025-9111 - WPBOT < 7.1.0 - Admin+ Stored XSS

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: Sept. 9, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Nov. 13, 2025, 9:15 p.m.
Total resulsts: 349182
Page 3951 of 34,919
ยซ previous page ยป next page
Filters